Multi Service Security Appliance IPCOM Sseries Multi Service Security Appliance IPCOM S Series Functions Overview July 2005 FUJITSU Ltd. 1 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
Bandwidth Control Bandwidth Control Function Efficient use of limited bandwidth and assuring response for mission-critical applications Allocate bandwidth by judging address, port #, applications or URLs Suited for VoIP applications or streaming applications (RTSP/RTP) Dynamically allocate bandwidth settings for dates, day of the week or time Bi-directional traffic control (BTC) achieves traffic control for inbound and outbound traffic. Network IPCOM S series Even allocation of bandwidth DB/Application server Web server QoS control for: DB/Application 50% Web 30% VoIP 20% VoIP 2 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
Bandwidth Control Traffic Monitoring & Analysis Obtains traffic status, and supports bandwidth control setting support QoS (bandwidth control) policy creation, and make large reduction in introduction cost Automatic detection of protocol & service in the network Operation by bandwidth control policy Collected Information: - Bandwidth usage - Packet size distribution - Protocol statistics - Service/application statistics traffic discovery operation obtain network status Lifecycle on QoS control traffic analysis bandwidth control policy creation 3 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
Link Link Load-balancing Link Load-balancing Function Distribution of bi-directional (outbound & inbound) traffic Supports various distribution method to select the most appropriate WAN WAN line status monitoring enables early detection of traffic route failure Stable line quality and highly reliable encryption communication provided by QoS control and IPSec-VPN WWW sites IPCOM S1000/S1200 Provider A IPCOM S1000/S1200 Provider A Internet Internet Provider B WWW sites Provider B outbound load-balancing inbound load-balancing 4 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
Firewall Firewall Firewall Function Protects internal network from illegal accesses Detection of illegal accesses and defense (discard) by access control Defense from service impairment (DoS/DDoS) attacks by IDP Intranet protection by network address translation Internal network General users Detection & Defense Internet IPCOM S Series Abnormality Intrusion, or service operation impairment Discard DMZ 5 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
IPsec-VPN IPsec-VPN Function VPN ality for secure internet use Secure VPN environment by IPsec tunneling High availability IPsec-VPN communication environment by 2 types of systems Hub and spoke type, which connects branches through centers Mesh type between branches Stable communication by avoiding path MTU problems using path MTU discovery Quick restoration of communication by automatic recovery of SA at destination server reboot Internet DB/Application server IPCOM S series IPCOM S series Web server IPsec tunneling * SA (Security Association) is a parameter definition required for IPsec communication. 6 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
SSL-VPN SSL-VPN Function Low cost anytime, anywhere connection solution for a secure traffic Special software not required at client. Low cost introduction and operation is enabled. By using encryption and authentication, secure remote access is realized on insecure networks such as internet. SSL communication termination (decryption) Check access right to internal network based on client authentication / user authentication IPCOM connects to internal network on behalf of users Internet SSL-VPN system Intranet SSL encryption DMZ Achieves high security and convenience Protect from the threat of tapping or tampering Achieves reliable and highly expandable network environment, by seamlessly integrating multiple s such as router, Firewall, or bandwidth control, etc. Web server 7 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
SSL SSL Accelerator SSL Accelerator Function Secure communication by Built-in SSL accelerator Improve performance of web servers by off-loading encryption / decryption processes of web servers to IPCOM Stable and highly reliable system with built-in SSL accelerator. Support SSLv2, SSLv3, and TLSv1 Load-balancing Web server Network IPCOM S2000/S2200 SSL accelerator HTTPS ( Encrypted data ) HTTP 8 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
High HighReliability Reliability Unit Redundancy Function Resume communication by ing to standby unit when trouble happens on active side. Network Synchronization active standby Network trouble Synchronization Monitoring each other by heartbeat message,while synchronizing connection and control information via synchronization path Method of monitoring other unit - Heart beat - Synchronization path monitoring - Data synchronization If trouble happens on active unit, service will be ed to standby unit and resumes a communication resumes communication 9 All Right Reserved, Copyright(c) FUJITSU Ltd.2005
Operation Management Operation Management Operation/Monitoring of IPCOM by a single PC Centralized monitoring by SNMP monitoring server Stores logging information (syslog) in an external server Operation status monitoring Web browser (QoS monitor ) Command operation terminal (Operation management CLI issue ) IPCOM administration PC Traffic monitoring Trouble monitoring Web browser Web browser (Traffic detection ) (Event monitor ) Traffic Discovery Error display on LCD panel SNMP trap syslog -event info. -logging info. error notification SNMP monitoring server /log server e-mail System administrator 10 All Right Reserved, Copyright(c) FUJITSU Ltd.2005